Install error on SCEP (system center endpoint protection) 4.7 on Windows 10 1703,1709

I'm having issue to push out SCEP 4.7 to Windows 10 specifically version 1703 and 1709. I don't have issue with 1607.
It seems like version compatiblity issue. but don't know how to fix this.

-Where can I check compatible version of SCEP for Windows 10 1709 ? Is there any Microsoft website track and provide this?
-How can I update the installation file to the updated version?


When I push out SCEP to Windows 10 170x, it throws this error message in System Configuration;

"Cannot complete the System Center Endpoint Protection installation. An error has prevented the System Center Endpoint Protection setup wizard from completing successfully. Please restart your computer and try again. Error code:0x80070643. Fatal error during installation."


And in client's laptop log;

<![LOG[Sending ack to MTC for task {9BCF7827-E04F-4C3A-8D8C-B943316A2D7F}]LOG]!><time="10:49:46.529+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epmtchelper.cpp:98">
<![LOG[SCEP client is not present, SCEP client will be installed with the latest AM policy.]LOG]!><time="10:49:46.533+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:953">
<![LOG[Sending message to external event agent to disable notification]LOG]!><time="10:49:46.533+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:960">
<![LOG[Sending message to endpoint ExternalEventAgent]LOG]!><time="10:49:46.533+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:1175">
<![LOG[Disable Startup Signature Update equals to false.]LOG]!><time="10:49:46.561+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:467">
<![LOG[Add the Disable Startup Signature Update settings to policy xml successfully.]LOG]!><time="10:49:46.564+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:471">
<![LOG[Create Process Command line: "C:\windows\ccmsetup\SCEPInstall.exe" /s /q /policy "C:\windows\CCM\EPAMPolicy.xml".]LOG]!><time="10:49:46.564+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:636">
<![LOG[Detail error message is : [EppSetupResult]
HRESULT=0x80070643
Description=Cannot complete the System Center Endpoint Protection installation. An error has prevented the System Center Endpoint Protection setup wizard from completing successfully. Please restart your computer and try again. Error code:0x80070643. Fatal error during installation.
]LOG]!><time="10:49:51.658+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:435">
<![LOG[start to send State Message with topic type = 2001, state id = 4, and error code = 0x80070643]LOG]!><time="10:49:51.658+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:1337">
<![LOG[Start to send state message.]LOG]!><time="10:49:51.658+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:1275">
<![LOG[Send state message successfully]LOG]!><time="10:49:51.667+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:1277">
<![LOG[Save new state 4, error code -2147023293, detail message 'Cannot complete the System Center Endpoint Protection installation. An error has prevented the System Center Endpoint Protection setup wizard from completing successfully. Please restart your computer and try again. Error code:0x80070643. Fatal error during installation.' to registry SOFTWARE\Microsoft\CCM\EPAgent\State]LOG]!><time="10:49:51.667+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:235">
<![LOG[Failed to install EP client with exit code = 0x80070643.]LOG]!><time="10:49:51.667+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="3" thread="3296" file="epagentimpl.cpp:579">
<![LOG[Register a timer here to check whether definition get updated in 130 minutes.]LOG]!><time="10:49:51.667+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:1164">
<![LOG[Firewall provider is installed.]LOG]!><time="10:49:51.668+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:808">
<![LOG[Installed firewall provider meet the requirements.]LOG]!><time="10:49:51.668+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:829">
<![LOG[start to send State Message with topic type = 2001, state id = 4, and error code = 0x80070643]LOG]!><time="10:49:51.668+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:1337">
<![LOG[Skip sending state message due to same state message already exists.]LOG]!><time="10:49:51.673+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:1268">
<![LOG[Endpoint is triggered by WMI notification.]LOG]!><time="10:49:51.674+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="9108" file="fepsettingendpoint.cpp:155">
<![LOG[Endpoint is triggered by WMI notification.]LOG]!><time="10:49:51.674+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="fepsettingendpoint.cpp:155">
<![LOG[File C:\windows\ccmsetup\SCEPInstall.exe version is 4.7.214.0.]LOG]!><time="10:49:51.677+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="9108" file="epagentutil.cpp:548">
<![LOG[Unable to query registry key (SOFTWARE\Microsoft\Microsoft Security Client), return (0x80070002) means EP client is NOT installed.]LOG]!><time="10:49:51.678+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="9108" file="epagentutil.cpp:181">
<![LOG[File C:\windows\ccmsetup\SCEPInstall.exe version is 4.7.214.0.]LOG]!><time="10:49:51.680+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:548">
<![LOG[Unable to query registry key (SOFTWARE\Microsoft\Microsoft Security Client), return (0x80070002) means EP client is NOT installed.]LOG]!><time="10:49:51.680+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:181">
<![LOG[Endpoint is triggered by message.]LOG]!><time="10:57:05.019+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="9556" file="fepsettingendpoint.cpp:59">
<![LOG[File C:\windows\ccmsetup\SCEPInstall.exe version is 4.7.214.0.]LOG]!><time="10:57:05.044+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="9556" file="epagentutil.cpp:548">
<![LOG[Unable to query registry key (SOFTWARE\Microsoft\Microsoft Security Client), return (0x80070002) means EP client is NOT installed.]LOG]!><time="10:57:05.044+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="9556" file="epagentutil.cpp:181">
<![LOG[Re-apply EP AM policy.]LOG]!><time="10:57:05.044+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="9556" file="fepsettingendpoint.cpp:108">
<![LOG[Endpoint is triggered by WMI notification.]LOG]!><time="10:57:05.673+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="fepsettingendpoint.cpp:155">
<![LOG[Firewall provider is installed.]LOG]!><time="10:57:05.675+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="9556" file="epagentutil.cpp:808">
<![LOG[Installed firewall provider meet the requirements.]LOG]!><time="10:57:05.675+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="9556" file="epagentutil.cpp:829">
<![LOG[File C:\windows\ccmsetup\SCEPInstall.exe version is 4.7.214.0.]LOG]!><time="10:57:05.678+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:548">
<![LOG[Unable to query registry key (SOFTWARE\Microsoft\Microsoft Security Client), return (0x80070002) means EP client is NOT installed.]LOG]!><time="10:57:05.678+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:181">
<![LOG[Sending ack to MTC for task {9BCF7827-E04F-4C3A-8D8C-B943316A2D7F}]LOG]!><time="10:57:05.678+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epmtchelper.cpp:98">
<![LOG[SCEP client is not present, SCEP client will be installed with the latest AM policy.]LOG]!><time="10:57:05.683+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:953">
<![LOG[Sending message to external event agent to disable notification]LOG]!><time="10:57:05.683+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:960">
<![LOG[Sending message to endpoint ExternalEventAgent]LOG]!><time="10:57:05.683+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:1175">
<![LOG[Disable Startup Signature Update equals to false.]LOG]!><time="10:57:05.703+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:467">
<![LOG[Add the Disable Startup Signature Update settings to policy xml successfully.]LOG]!><time="10:57:05.707+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:471">
<![LOG[Create Process Command line: "C:\windows\ccmsetup\SCEPInstall.exe" /s /q /policy "C:\windows\CCM\EPAMPolicy.xml".]LOG]!><time="10:57:05.707+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:636">
<![LOG[Detail error message is : [EppSetupResult]
HRESULT=0x80070643
Description=Cannot complete the System Center Endpoint Protection installation. An error has prevented the System Center Endpoint Protection setup wizard from completing successfully. Please restart your computer and try again. Error code:0x80070643. Fatal error during installation.
]LOG]!><time="10:57:10.058+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:435">
<![LOG[EP State and Error Code didn't get changed, skip resend state message.]LOG]!><time="10:57:10.058+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:161">
<![LOG[State 4, error code -2147023293 and detail message are not changed, skip updating registry value]LOG]!><time="10:57:10.058+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:213">
<![LOG[Failed to install EP client with exit code = 0x80070643.]LOG]!><time="10:57:10.058+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="3" thread="3296" file="epagentimpl.cpp:579">
<![LOG[One timer is already created and running, skip the new timer here.]LOG]!><time="10:57:10.058+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:1155">
<![LOG[Firewall provider is installed.]LOG]!><time="10:57:10.061+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:808">
<![LOG[Installed firewall provider meet the requirements.]LOG]!><time="10:57:10.061+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:829">
<![LOG[start to send State Message with topic type = 2001, state id = 4, and error code = 0x80070643]LOG]!><time="10:57:10.061+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentimpl.cpp:1337">
<![LOG[Skip sending state message due to same state message already exists.]LOG]!><time="10:57:10.224+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:1268">
<![LOG[Endpoint is triggered by WMI notification.]LOG]!><time="10:57:10.224+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3424" file="fepsettingendpoint.cpp:155">
<![LOG[Endpoint is triggered by WMI notification.]LOG]!><time="10:57:10.224+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="fepsettingendpoint.cpp:155">
<![LOG[File C:\windows\ccmsetup\SCEPInstall.exe version is 4.7.214.0.]LOG]!><time="10:57:10.224+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3424" file="epagentutil.cpp:548">
<![LOG[Unable to query registry key (SOFTWARE\Microsoft\Microsoft Security Client), return (0x80070002) means EP client is NOT installed.]LOG]!><time="10:57:10.224+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3424" file="epagentutil.cpp:181">
<![LOG[File C:\windows\ccmsetup\SCEPInstall.exe version is 4.7.214.0.]LOG]!><time="10:57:10.240+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:548">
<![LOG[Unable to query registry key (SOFTWARE\Microsoft\Microsoft Security Client), return (0x80070002) means EP client is NOT installed.]LOG]!><time="10:57:10.240+300" date="01-07-2018" component="EndpointProtectionAgent" context="" type="1" thread="3296" file="epagentutil.cpp:181">
Sungpill HanAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Hello ThereSystem AdministratorCommented:
Please check if the clients are in pending reboot status. This may cause error 0x80070643.
Remove any existing security programs
Ensure that the Windows Installer service is running

Also check this article and this one.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Sungpill HanAuthor Commented:
It's found that if there's an antimalware software, SCEP management module remote installation will fail on Windows 10. Once Kaspersky was deleted, in about a hour, Windows Defender became active, then in about another 3  hours, SCEP was installed.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows 10

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.